ShellBags USB Forensics: A Worked Investigation Example
A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.
Series
4 posts in this series. Read them in order or jump to any one.
A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.
How ShellBags record browsing inside ZIP files and other archives in Explorer, what the compressed folder items contain, and how to interpret archive paths.
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
What ShellBags cannot prove, what never creates them, how cleaners like PrivaZer or CCleaner remove them, and the traces deletion and tampering leave.
A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.
How ShellBags record browsing inside ZIP files and other archives in Explorer, what the compressed folder items contain, and how to interpret archive paths.
Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.
What ShellBags cannot prove, what never creates them, how cleaners like PrivaZer or CCleaner remove them, and the traces deletion and tampering leave.